Originally Posted by slackamp
What does the line ":OUTPUT ACCEPT [12325:2319098]" mean? will it cause any trouble? What would happen if I put [0:0]?
The output of iptables-save
is an abbreviated listing of your firewall rules that iptables-restore
can use to restore the state of the firewall. The line you ask about says the policy for the OUTPUT chain is DROP. The numbers in brackets are packet and byte counts for that policy that can be restored with iptables-restore
. If you set them to zero, then you just lose that information.
I hope what you listed isn't the entire contents of that file. If so, all
incoming packets will be dropped, including loopback packets. Normally you would want to at least accept loopback.